LOW
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL
Published Nov 16, 2013
3.5
LOWCVSS 2.0
EPSS 1.45%
Description
Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Affected products
No data.
OR
- 7.0
- 7.0.0.1
- 7.0.0.2
- 7.0.0.3
- 7.0.0.4
- 7.0.0.5
- 7.0.0.6
- 7.0.0.7
- 7.0.0.8
- 7.0.0.9
- 7.0.0.10
- 7.0.0.11
- 7.0.0.12
- 7.0.0.13
- 7.0.0.14
- 7.0.0.15
- 7.0.0.16
- 7.0.0.17
- 7.0.0.18
- 7.0.0.19
- 7.0.0.21
- 7.0.0.22
- 7.0.0.23
- 7.0.0.24
- 7.0.0.25
- 7.0.0.27
- 7.0.0.29
- 8.0.0.0
- 8.0.0.1
- 8.0.0.2
- 8.0.0.3
- 8.0.0.4
- 8.0.0.5
- 8.0.0.6
- 8.0.0.7
- 8.5.0.0
- 8.5.0.1
- 8.5.0.2
- 8.5.5.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- http://www-01.ibm.com/support/docview.wss?&uid=swg21651880 x_refsource_CONFIRMVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1PM96477 vendor-advisoryx_refsource_AIXAPAR
- http://www.securityfocus.com/bid/63778 vdb-entryx_refsource_BID
- https://exchange.xforce.ibmcloud.com/vulnerabilities/87480 vdb-entryx_refsource_XF
| Link | Providers | Tags |
|---|---|---|
| http://www-01.ibm.com/support/docview.wss?&uid=swg21651880 | x_refsource_CONFIRMVendor Advisory | |
| http://www-01.ibm.com/support/docview.wss?uid=swg1PM96477 | vendor-advisoryx_refsource_AIXAPAR | |
| http://www.securityfocus.com/bid/63778 | vdb-entryx_refsource_BID | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/87480 | vdb-entryx_refsource_XF |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Nov 16, 2013
Updated Aug 6, 2024
Reserved Aug 22, 2013
Link CVE-2013-5418
CISA Vulnrichment
Updated n/a